Medium severity6.5NVD Advisory· Published Jun 1, 2022· Updated Jun 17, 2026
CVE-2022-29232
CVE-2022-29232
Description
BigBlueButton is an open source web conferencing system. Starting with version 2.2 and prior to versions 2.3.9 and 2.4-beta-1, an attacker can circumvent access controls to obtain the content of public chat messages from different meetings on the server. The attacker must be a participant in a meeting on the server. BigBlueButton versions 2.3.9 and 2.4-beta-1 contain a patch for this issue. There are currently no known workarounds.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
5cpe:2.3:a:bigbluebutton:bigbluebutton:*:*:*:*:*:*:*:*+ 4 more
- cpe:2.3:a:bigbluebutton:bigbluebutton:*:*:*:*:*:*:*:*range: >=2.2.0,<2.3.9
- cpe:2.3:a:bigbluebutton:bigbluebutton:2.4:alpha1:*:*:*:*:*:*
- cpe:2.3:a:bigbluebutton:bigbluebutton:2.4:alpha2:*:*:*:*:*:*
- (no CPE)range: >=2.2, <2.3.9 and <2.4-beta-1
- (no CPE)range: >= 2.2, < 2.3.9
Patches
Vulnerability mechanics
References
4- github.com/bigbluebutton/bigbluebutton/pull/12861nvdPatchThird Party Advisory
- github.com/bigbluebutton/bigbluebutton/security/advisories/GHSA-3fqh-p4qr-vfm9nvdPatchThird Party Advisory
- github.com/bigbluebutton/bigbluebutton/releases/tag/v2.3.9nvdRelease NotesThird Party Advisory
- github.com/bigbluebutton/bigbluebutton/releases/tag/v2.4-beta-1nvdRelease NotesThird Party Advisory
News mentions
0No linked articles in our index yet.